Privacy Policy

A single policy covering both Cinderella mobile applications — the Client app used to book cleaning services and the Provider app used by professional cleaners and their teams to offer services on our platform.

This Privacy Policy explains how Schwarzschild Group Limited (“we”, “us”, “our”),
registered at 58 New Bedford Road, LUTON – LU1 1SH, United Kingdom (GB), email office@schwarzschildgroup.com, processes personal data when you use the Cinderella Client and Cinderella Provider mobile applications. Both Apps are covered by this policy; where a specific data category applies only to one App, we say so next to the relevant heading.

We act as the controller for the personal data described below and comply with the EU General Data Protection Regulation (GDPR) and applicable national laws in Romania, Germany and Hungary. For the formal compliance framework — legal bases, international-transfer safeguards and detailed procedures for exercising your rights — please see our GDPR compliance notice.

01Data we collect

1.1 Account and identity

  • Email address and password (stored hashed on our servers).
  • First name, last name, country code, preferred language.
  • Phone number, verified via a one-time password (OTP) sent by SMS.
  • In the Provider App additionally: whether you operate
    solo or as a team manager, and – if applicable,
    the declared size of your team.

1.2 Business and tax data — Provider App only

Because the Provider App is a professional tool, providers must supply
during registration:

  • VAT number.
  • Company or trade-registry registration number.
  • Billing address (which may differ from the base of operation).

1.3 Identity and certification documents

To use certain features, you may be asked to upload:

  • A photograph of a government-issued identity document and your
    personal identification number (both Apps, when identity verification
    is required).
  • Any professional certifications required to offer cleaning services
    in your market (Provider only).

Documents are transmitted to our backend over an encrypted connection,
are stored with access restricted to authorised verification staff,
and are marked with a verification status. When a document is rejected,
the reason is returned to you inside the App.

1.4 Profile photo

An optional profile picture uploaded from your camera or photo library.

1.5 Location data

When you use location-based features the App requests
foreground access to your device’s precise GPS
coordinates. Coordinates are reverse-geocoded to a human-readable
address and sent to our backend.

  • In the Client App, location is used to set the address for a service
    booking and to display nearby available services.
  • In the Provider App, location is used to set the provider’s
    base of operation, to show nearby job offers, and — for
    team managers — to set the base of operation of team members.

We do not collect background location and we do not continuously track
your device.

Recent addresses you have used are cached in encrypted device storage
on your device for your convenience.

1.6 Service preferences — Provider App only

Providers choose which services (e.g. residential, office,
deep-cleaning tasks) they are willing to accept at each of their
registered locations. These preferences are stored on our backend and
used to match providers with compatible jobs.

1.7 Communications

  • Chat messages, images and metadata (sender name, sender identifier,
    timestamp) exchanged with the other party of a job or with our
    support team.
  • Emails you send us at
    office@schwarzschildgroup.com.

Chat messages are stored in Google Firebase Firestore.

1.8 Payment and billing data

Both Apps use a subscription model — in the Client App to access
booking features, in the Provider App to access the platform and
receive job offers. In both cases we hold:

  • Card metadata only: the last four digits, brand (e.g. Visa/Mastercard)
  • Subscription status, last and next billing dates, price and currency.


Full payment card data never touches the App and is not stored on
our servers.

Card payments are processed by our payment provider,
Stripe, whose privacy notice applies to the card data
you enter
(
privacy notice
).

1.9 Device and technical data

  • A push-notification device token issued by Firebase Cloud Messaging
    and a composite device identifier used to route notifications.
  • Diagnostic attributes attached to crash reports: device brand,
    device model, device type, App version, build number and bundle
    identifier.
  • Crash stack traces and error context.

02Third-party service providers

The following processors act on our behalf for both Apps. Data is
transmitted over encrypted connections and processed under contractual
data-protection terms.

Provider Purpose Data shared
Google Firebase Authentication Sign-in tokens User identifier, custom auth token
Google Firebase Cloud Messaging Push notification delivery Device push token, notification payloads
Google Firebase Firestore Real-time chat storage Chat messages, image references, sender identifier, timestamps
Google Firebase Crashlytics Crash and error diagnostics Crash reports and device attributes
Google Maps SDK & Google Places API Map display and address autocomplete Approximate coordinates, address search queries
Expo (reverse geocoding) Convert coordinates to a readable address Latitude and longitude
Stripe Subscription and card payment processing Card data entered with the provider, billing metadata,
invoicing information
Gateway API Delivering phone verification SMS Phone number, one-time code

03Retention

We keep personal data only for as long as it is needed for the purpose
for which it was collected, or for as long as we are required to keep
it by law (for example, tax and invoicing obligations). When you delete
your account, your personal data is removed after a short grace period,
except for records we are legally obliged to retain.

04Your rights

4.1 Your rights at a glance

Under the GDPR you have the right to access, correct, delete, restrict,
port and object to the processing of your personal data, and to
withdraw consent for any permission granted at the OS level.
For the formal procedures, response times and how to exercise each
right, please see our
GDPR compliance notice
or email

office@schwarzschildgroup.com
.

4.2 Deleting your account

You can delete your account at any time from within the App under
Profile → My Account → Delete Account. Your account is placed
in a grace period during which you can cancel the deletion from the
same screen; after the grace period the account and associated personal
data are removed.

05Device permissions

Both Apps request the same set of operating-system permissions on iOS
and Android. The table below shows how each permission is used in each
App.

Permission Client App usage Provider App usage
Location (while using the App) Show your address on the map and select the correct service
location.
Set your base of operation, display nearby jobs, and adjust
team members’ base locations.
Camera Take photos for your profile picture and identity documents. Take photos for your profile picture, identity documents and
certifications.
Photo library Choose existing photos for your profile picture, identity
documents and chat.
Choose existing photos for your profile picture, identity
documents, certifications and chat.
Notifications Deliver push notifications about your jobs and chats. Deliver push notifications about job offers, chats and team
assignments.
Calendar Add scheduled jobs to your calendar (optional). Add scheduled jobs to your calendar (optional).
Reminders (iOS only) Set reminders for upcoming jobs (optional). Set reminders for upcoming jobs (optional).
Internet Communicate with our backend and third-party services. Communicate with our backend and third-party services.

06Security

  • All communication with our backend uses HTTPS with modern TLS.
  • Authentication uses short-lived JWT access tokens and refresh tokens
    stored in the OS Keychain / Keystore via the platform’s secure-storage
    APIs.
  • Access to identity documents, certifications, business data and
    subordinate records on our backend is restricted to authorised
    personnel only.

07Cookies, analytics and advertising

Neither App uses cookies, advertising identifiers (AAID / IDFA),
third-party analytics SDKs or advertising.

The only diagnostic data we collect is the crash telemetry described
in 1.9.